๐Ÿ” CVE Alert

CVE-2026-19429

HIGH 8.8

Jenkins Project Jenkins - Symlink Target Validation Bypass Arbitrary File Read

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

Jenkins FilePath.untarFrom() (all versions) validates symlink destinations but not targets, bypassing CVE-2026-33001. Any user with Item/Build access triggers malicious tar extraction via POST /job/{name}/build, writing persistent symlinks into the Jenkins tool cache. Symlinks to secrets/master.key and credentials.xml read via GET /job/{name}/lastBuild/consoleText enable offline AES decryption of all stored credentials and admin RCE. Symlinks to /dev/zero or blocking FIFOs hang build executors.

CWE CWE-59
Vendor jenkins project
Product jenkins
Ecosystems
Industries
Technology
Published Aug 10, 2026
Last Updated Aug 10, 2026
Stay Ahead of the Next One

Get instant alerts for jenkins project jenkins

Be the first to know when new high vulnerabilities affecting jenkins project jenkins are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Jenkins Project / Jenkins
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/jenkinsci/jenkins jenkins.io: https://www.jenkins.io/security/advisories/2026-03-19/

Credits

Jamshed Yergashvoyev (CVE GUY | TuranSec)